//Cyber.Engineer

O365: Disable legacy authentication

Using legacy authentication may, in some circumstances, increase the risk of account compromise due to how the password is transmitted and stored.

Azure Sentinel: Adding Threat Indicators Manually

You can either have an automated Cyber Threat Intelligence feed (STIX/TAXII) or your threat indicators can be added manually in the form of IP, Domain, URL File hash. Let's run through the manual process.

Azure Sentinel: Querying for your Cyber Threat Indicators

All CTI entries aren't just available to view in the "Threat Intelligence" page - they are stored in the Log Analytics Workspace table "ThreatIntelligenceIndicator". Here you will find the manually submissions, but also any automated feeds from STIX/TAXII.

General Availability of Azure Sentinel Threat Intelligence in Public and Azure Government cloud

General Availability of Azure Sentinel Threat Intelligence in Public and Azure Government cloud

Saying goodbye to Exchange Online basic auth

A recent announcement from Microsoft regarding Exchange Online and Basic Auth - finally making that last push to get it removed.

//Cyber.Engineer © 2026